Tag: identity theft
343 articles

OAuth Grants Expose Hidden Attack Vector in Enterprise Workspaces
Unmanaged OAuth grants are a ticking time bomb in enterprise workspaces, with 80% of security leaders recognizing them as a critical or significant risk. A recent attack by threat actor UNC6395 exploited valid OAuth refresh tokens to breach Salesforce environments of over 700 organizations, highlighting the devastating consequences of neglecting OAuth security.

Pharmacist Indicted for Spying on Co-Workers with Cyber Tools
A pharmacist in Maryland has been indicted for allegedly spying on nearly 200 coworkers and individuals over eight years using cyber tools, breaching trust and violating digital boundaries. Matthew Bathula faces federal charges for unauthorized computer access and aggravated identity theft.

Fraudsters Target Credit Unions with Structured Loan Scams
Fraudsters are now targeting credit unions with sophisticated loan scams, using stolen identities and social engineering to exploit lending workflows. In fact, auto lending fraud exposure is expected to hit $9.2 billion by 2025, making it a lucrative target for these scammers.

ADT Breach Exposes 5.5 Million in ShinyHunters Hack
A massive data breach at ADT has put 5.5 million people's personal info at risk, including names, phone numbers, addresses, and sensitive details like dates of birth and Social Security numbers. The breach, linked to the ShinyHunters extortion group, has left millions vulnerable to potential identity theft and scams.

ADT Confirms Cyber Intrusion After ShinyHunters Extortion Attempt
ADT confirmed a cyber intrusion on April 20, swiftly isolating the breach and collaborating with incident responders and law enforcement to contain the damage. The compromised data included sensitive information like names, phone numbers, and addresses, as well as dates of birth and partial Social Security numbers for a smaller subset of individuals.

Hackers Expose 19M Records in French Government Agency Breach
A recent data breach at France's Agence nationale des titres sécurisés (ANTS) may have compromised 19 million records, but thankfully, no action is required from users - for now. The agency is notifying affected individuals and advising them to stay vigilant for suspicious contacts.

France's ID Agency Probes Breach Claiming 19M Records Stolen
A massive data breach at France's ID agency may have exposed a staggering 19 million records, putting the personal info of nearly a third of the country's population at risk. The breach, detected on April 15, involves the theft of sensitive data, including login IDs, names, email addresses, and dates of birth.

Scotland Hacker Pleads Guilty in Scattered Spider Cybercrime Case
Meet Tyler Robert Buchanan, the 24-year-old mastermind behind the notorious Scattered Spider cybercrime gang, who has pleaded guilty to federal charges of conspiracy and identity theft. With a potential 22-year prison sentence looming, Buchanan's guilty plea marks a major win for law enforcement in the fight against cybercrime.

Scattered Spider Member Pleads Guilty to $8 Million Crypto Heist
A 24-year-old British hacker, Tyler Robert Buchanan, has pleaded guilty to masterminding an $8 million crypto heist as part of the notorious Scattered Spider cybercrime group. His downfall began with a trail of seemingly harmless text messages that ultimately led to his guilty plea.

British Hacker Pleads Guilty to Crypto Theft Charges
A British hacker, allegedly the mastermind behind the notorious Scattered Spider cybercrime collective, has pleaded guilty to wire fraud and aggravated identity theft charges in a US court, dealing a significant blow to the shadowy network. This guilty plea marks a major win for law enforcement and raises important questions about the future of cybercrime and online security.

Scattered Spider Operative Pleads Guilty to US Federal Charges
In a major breakthrough, Tyler Robert Buchanan, a senior figure in the notorious Scattered Spider cybercrime group, has pleaded guilty to federal charges, bringing an end to his digital crime spree. Buchanan admitted to conspiracy to commit wire fraud and aggravated identity theft in a US federal district court.

DraftKings Hacking Scheme Draws 30-Month Prison Sentence
A 23-year-old man from Memphis, Tennessee, has been sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts, a brazen crime that left countless victims feeling vulnerable and betrayed. The case highlights the growing threat of account-fraud markets, where stolen credentials are bought and sold like commodities.

Hackers Target Asia Pacific with URL-Based Threats
In Asia Pacific, hackers are ditching traditional tactics and using URL-based threats to gain easy access to your digital life - with just one click, your security can be compromised. This emerging threat landscape is redefining how we think about online identity, access, and trust.

Credential Theft Evolves, Outpaces Breach Monitoring Defenses
Imagine the keys to your online kingdom being quietly copied and stolen before you even notice - that's the alarming reality of credential theft, where infostealers are harvesting sensitive info at scale, often bypassing traditional defenses. Simple breach monitoring just can't keep up with this modern threat.

NIST Unveils Critical Identity Verification Standard for Federal Workers
The National Institute of Standards and Technology (NIST) has just unveiled a groundbreaking identity verification standard to safeguard the identities of federal workers and contractors, addressing the growing threat of identity theft and cybersecurity breaches. This critical new standard is a major step forward in protecting sensitive information and preventing unauthorized access.

Phishing Surges with Alarming New Tactics This Tax Season
Tax season is here, and with it, a surge in phishing attacks that could leave you vulnerable to identity theft and financial loss. Don't wait until it's too late - stay ahead of cybercriminals and protect your sensitive info from their alarming new tactics.

France database: Exclusive critical leak of 1.2M accounts
An unknown attacker reportedly exfiltrated 1.2 million bank-account records from France’s central database, turning administrative efficiency into a nationwide privacy and security crisis. Read on to see what happened, who’s at risk, and how one failed lock can expose millions.

Security Leaders Exclusive: Damaging Marquis Breach
The Marquis data breach exposed hundreds of thousands of tax‑credit records — and it asks a blunt question: when trust is the currency, who pays? Security leaders say this wasn’t a freak accident but a familiar mix of human error, misconfiguration and governance gaps that proves convenience still too often outpaces caution.

Stay Safe Online: Must-Have Affordable Black Friday Tips
Don’t let a great Black Friday bargain turn into identity theft — these affordable Black Friday tips (use a VPN, avoid open Wi‑Fi for payments, turn off auto‑connect, and keep devices updated) help you shop safely and smart. Shop confidently this holiday season with a few easy, low‑cost habits that protect your data and wallet.

Coupang Confirms Stunning, Damaging Leak of 34M Customers
If youve shopped on Coupang, keep an eye on your accounts: the company confirmed a suspected cyber-attack exposed personal data for about 34 million customers, prompting a police probe and warnings about fraud. The breach lays bare how one‑click convenience concentrates risk and is fueling renewed calls for tougher data safeguards.

Proton Exclusive: Alarming 300M Records Compromised
More than 300 million records have surfaced on the dark web — a startling tally that often mixes new leaks, resurfaced data and partial overlaps. Here’s what that number really means for your emails, passwords and IDs, and the simple steps you can take right now to protect yourself.

Dentsu Exclusive: Critical Staff Warning After Merkle Raid
A terse Dentsu alert revealed payroll and bank details may have been exposed in a cyberattack on Merkle, turning a corporate incident into a personal scramble to protect paychecks, identities and livelihoods.

180,000 Records of PII Exposed: Exclusive Critical Leak
Heads up: roughly 180,000 customer records — including names, payment card details and other PII — were left in an unsecured repository, putting people at risk of fraud and companies on the hook for costly regulatory and reputational fallout.

180,000 Records Exposed: Exclusive Critical Threat
When an unsecured repository exposed 180,000 records—names, contacts and payment card numbers—those people were suddenly vulnerable to fraud. It’s a stark reminder of how tiny cloud misconfigurations and lax access controls can turn convenience into widespread risk.